docs: hub v0.61.0 Customer RESET — REPORT/CONTEXT + ep0 runbook §10 (tenantsync v1.1.0 deprovision, live-drilled)
This commit is contained in:
+16
@@ -3,6 +3,22 @@
|
||||
> Created with the REUSE.md rollout (2026-07-03). Authoritative history: `hub/CHANGELOG.md` (hub),
|
||||
> `website/CHANGELOG.md`, `scripts/CHANGELOG.md`; end-of-task detail in `REPORT.md`.
|
||||
|
||||
- **2026-07-17 — CUSTOMER RESET SHIPPED: hub v0.61.0 + felhom-tenantsync v1.1.0 (LIVE).** The middle
|
||||
lifecycle tier (host delete < RESET < customer Delete). One operator action → pre-first-install: all
|
||||
OPERATIONAL state dies (offsite repo, PBS namespace+backups, DR recipe, one-time secret, claim state,
|
||||
retained escrow custody); IDENTITY + basic config (incl. the offsite tier CHOICE) + provenance + events
|
||||
SURVIVE. Rulings: separate escrow-custody ack; clears claim (fresh code next onboarding); REFUSES while
|
||||
any host row exists; live-counted confirm inventory. Discipline: external teardown FIRST, DB purge LAST,
|
||||
every leg idempotent → partial run re-runs from the top (purge withheld until externals ok). New:
|
||||
`store/customer_reset.go` (journal+inventory+ack-gated purge), `claim.ResetToUnclaimed`,
|
||||
`offsite.{Deprovision,OffsiteIdentifier,ClearProvisionedDescriptor}`, `tenantsync.Deprovision` +
|
||||
`felhom-tenantsync.sh` **deprovision** op (v1.1.0, destroys ns+groups+token, shared user untouched),
|
||||
`web/customer_reset.go` (GET inventory JSON / POST orchestration) + an **amber** RESET card distinct
|
||||
from the red Danger-zone Delete. Red-proofs: ack-gate + partial-failure resumability (both proven red).
|
||||
**Live-drilled on ep0** (throwaway `drill-reset-01` with a real backup): deprovision `deleted:true`,
|
||||
idempotent re-run `deleted:false`, all 3 real tenants survived. Hetzner-delete + the password-gated web
|
||||
POST covered by tests (offsite Deprovision mirrors live-proven ReissueCredentials). See REPORT.md.
|
||||
|
||||
- **2026-07-17 — HOST-DELETE DEMOTES ESCROW: hub v0.60.1 (LIVE).** Closes the v0.60.0 review gap:
|
||||
`DeleteHost(deleteEscrow=true)` now DEMOTES the current escrow blob into `host_escrow_superseded`
|
||||
(copy-before-delete, same tx) + spares existing superseded rows — never destroys custody. The
|
||||
|
||||
Reference in New Issue
Block a user